SFTP Vulnerability in SCALANCE LPE9403 by Siemens
CVE-2025-27395
8.6HIGH
Summary
A security flaw has been identified in the SCALANCE LPE9403 device, where the SFTP functionality does not adequately restrict the scope of accessible files and the privileges assigned. This weakness could allow an authenticated, highly-privileged remote attacker to gain unauthorized read and write access to arbitrary files, potentially compromising the system's integrity and confidentiality. It is crucial for users to assess their deployment and apply necessary remediations to secure their environments.
Affected Version(s)
SCALANCE LPE9403 0
References
CVSS V4
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved